Trust
Security and GDPR
What is held, who can reach it, how it is proved, and how it is erased.
The record is the product
A register is only worth keeping if it cannot be quietly rewritten afterwards. Check-ins, movements, drills and notices in CheckSteady are append-only: they cannot be edited or deleted by a staff member, a supervisor, an administrator, or by us. Every entry carries who recorded it and when, and nobody can act as somebody else.
Hosted in the EU
Frankfurt, encrypted in transit and at rest. No third-party analytics, trackers or external fonts.
Separated by construction
Each centre has its own database schema. One centre cannot read, change, export or erase another's records, and the tests prove it.
Data minimisation
Lists carry a name and what the screen needs. Dates of birth and identity numbers appear only on a record opened deliberately — and each opening is logged.
Roles in the database
Staff record. Supervisors also manage the register. Administrators also manage accounts and run export and erasure. The rules are enforced below the screen.
Subject access and erasure
A subject access request is one click: a resident's complete file, ready to send. Erasure runs on a schedule for departed residents and is itself logged, so you can evidence that it happened and when. An export asks for the reason it was taken, and that reason is kept with it.
Accounts and devices
Every staff member has their own account, because attribution is the point. Sessions last a shift rather than a fortnight, shared tablets lock after an idle period the centre sets, and sign-in supports a second factor. A password is never set for somebody by an administrator; a link is sent, and only its owner uses it.
Common questions
Where is the data stored?
In the European Union — Frankfurt — encrypted in transit and at rest. Nothing is sent to a third party: the application talks only to its own service, and there are no analytics, trackers or external fonts on the app.
Can an administrator edit or delete a check-in?
No. Check-ins, movements, drills and notices are append-only and cannot be altered or removed by anyone, at any level, including us. A correction is recorded as a new entry alongside the original.
How is one centre kept separate from another?
Each centre's records live in their own separate database schema, so isolation is structural rather than a filter somebody has to remember to apply. A mistake produces an error, not another centre's residents.
How do you handle a subject access request?
One click produces a resident's complete file — their record, their check-ins, their movements and their history — ready to send.
How is data erased?
Departed residents can be erased on a schedule, and the erasure itself is logged so you can evidence that it happened. Ending a contract is a separate, deliberate act with its own confirmation, never a side effect of a trial lapsing.
Who can see a resident's identity number?
Only staff who open that resident's own record, and only supervisors and administrators can change it. Numbers never appear in a list, and every opening of a record is written to an access log.
What stops a shared tablet being left signed in?
An idle lock, with the number of minutes set by the centre, and sessions that last a shift rather than a fortnight. Roles are enforced in the database itself, not only on the screen, so a refusal cannot be clicked past.
Try it on your own site
Start a free trial and have a look around — with sample residents to explore, or empty and ready for your own list. No card, and nothing to install.